Security & compliance · Qatar
Edrak and the Personal Data Privacy Protection Law
The PDPPL sets the rules for handling personal data in Qatar. Edrak reads personal data only when a workflow needs it, records where it was read or written, and keeps it inside the boundary you set.
- PDPPL
- Law No. 13 of 2016. Personal data protection and privacy, supervised by the NCSA's data privacy function.
- Applies to
- Any organisation processing personal data electronically in Qatar, except where financial-centre or free-zone regimes apply instead.
- Where Edrak stands
- Edrak acts as a processor under your instructions. Our data handling is mapped to the PDPPL and our contract terms reflect it. Controller obligations remain yours.
What the PDPPL requires
The law and its implementing guidelines set out obligations for controllers and processors. These four are the ones an AI platform has to answer for.
Basis
Lawful processing and purpose
Personal data processed for legitimate, specified purposes, with consent where required.
Rights
Individual rights
Access, correction, erasure and objection, with timelines for response.
Security
Security and breach notification
Appropriate safeguards and notification of breaches to the regulator and affected individuals.
Special
Special nature data
Additional permission requirements for health, ethnic, religious, criminal and children's data.
How Edrak supports your PDPPL obligations
The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.
Purpose and minimisation
Edrak: Each workflow declares what data it reads and why. Edrak retrieves only what the step needs and does not retain personal data beyond the workflow unless you configure it to.
You: Defining lawful purposes and the retention your policies allow.
Individual rights
Edrak: Records show where personal data was read or written, so access, correction and deletion requests can be traced through every workflow.
You: Receiving and fulfilling requests within statutory timelines.
Cross-border transfers
Edrak: Deployment options keep data in-country. Model routing lets you stop personal data leaving your boundary while still using hosted models for other work.
You: Assessing transfer conditions and approving any exceptions.
Processor terms
Edrak: Contract terms set out Edrak's role, sub-processors, security measures and breach notification, in the form your regulator expects.
You: Registering processing activities and appointing a privacy officer where required.
Records
Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.
You: Retention periods and breach-notification timelines.
Identity and access
Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.
You: Identities, roles, and joiner, mover and leaver processes.
For your security and compliance teams
We share a requirement-by-requirement mapping to the PDPPL frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.
Talk to our teamThe PDPPL issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.

